Telia: CRL signature algorithm property non-conformance for EC issuer key
Categories
(CA Program :: CA Certificate Compliance, task)
Tracking
(Not tracked)
People
(Reporter: antti.backman, Assigned: antti.backman)
Details
(Whiteboard: [ca-compliance] [crl-failure])
Preliminary Incident Report
This preliminary incident report for issued CRLs by Telia EC TLS DV CA v4 received as a Certificate Problem report 2026-09-23 15:51 UTC (report was acknowleged by Telia CA to the reporter as actionable 2026-09-24 08:56 UTC).
After full PKI review following CAs were determined to have the same issue.
- Telia EC TLS Root CA v3
- Telia EC TLS DV CA v4
- Telia EC Email Root CA v3 (no issuing CAs)
- Telia EC Client Root CA v3 (no issuing CAs)
- Telia EC Signing Root CA v3 (no issuing CAs)
Except for Telia EC TLS DV CA v4, the PKIs do not issue any certificates nor have issuing CAs. Telia EC TLS DV CA v4 is not made available for subscribers, it is only issuing required test certificates to meet requirements set forth for publicly trusted TLS PKIs.
Mentioned in the CPR and subsequently confirmed in our internal review, the linting tools we're currenlty using for CRL verifications do not detect either of the issues.
Incorrect signature algorithm is due to incorrect CA configuration setting made during finalization of the CAs. The parameters-field issue is confirmed by Telia CA's CA software vendor for being a defect in the software, when signature is generated for the CRL.
We will continue our detailed review and preparation to submit Full Incident Report no later than 14:00 UTC October the 8th 2026.
Summary
-
Incident description:
- Issue with all CRLs is the same, incorrect signature algorithm of
ecdsaWithSHA256(OBJECT IDENTIFIER 1.2.840.10045.4.3.2) used when signing the CRL for EC-384 issuer keys and issue withsignatureAlgorithm-field having inAlgorithmIdentifierfieldparameterswith valueNULL, which is in violation of RFC 5758 section 3.2.
- Issue with all CRLs is the same, incorrect signature algorithm of
-
Relevant policies:
- CA/Browser Forum TLS Baseline requirements, 7.1.3.2.2 ECDSA, Telia Server Certificates CP/CPS 7.1.3.2, IETF RFC 5758 Section 3.2
-
Source of incident disclosure:
- Third Party Reported
Updated•21 hours ago
|
Description
•